🔐 CVE Alert

CVE-2026-9058

UNKNOWN 0.0

Improper Certificate Verification in Szafir SDK

CVSS Score
0.0
EPSS Score
0.3%
EPSS Percentile
23th

For untrusted certificates that contain the "Authority Information Access - caIssuers URI" extension, Szafir SDK will automatically download the parent CA certificate from the specified URL and will import it to its trust store as a "nonqualified" certificate. In such a case, Szafir SDK returns a success status code of 0 ("Positively verified") upon successful cryptographic verification and a certificate status of "nonqualified". For other types of untrusted certificates, Szafir SDK returns a success status code of 0 ("Positively verified") upon successful cryptographic verification and a certificate status of "nondetermined". This may lead integrating applications to incorrectly treat the digital signature as valid despite an untrusted certificate chain. This flaw enables authentication bypass and user impersonation: (1) in use-cases other than qualified certificate authentication, or (2) if the qualified certificate authentication use-case is not correctly implemented by the integrating application. This issue was fixed in version 1.8.463.2.

CWE CWE-637 CWE-393 CWE-295
Vendor krajowa izba rozliczeniowa
Product szafir sdk
Published May 25, 2026
Last Updated Jul 23, 2026
Stay Ahead of the Next One

Get instant alerts for krajowa izba rozliczeniowa szafir sdk

Be the first to know when new unknown vulnerabilities affecting krajowa izba rozliczeniowa szafir sdk are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Krajowa Izba Rozliczeniowa / Szafir SDK
0 < 1.8.463.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.pl: https://cert.pl/posts/2026/05/CVE-2026-9058 elektronicznypodpis.pl: https://www.elektronicznypodpis.pl/

Credits

Michał Leszczyński (icedev.pl)